VIM (VIsual editor iMproved) is an updated and improved version of the
vi editor. Vi was the first real screen-based editor for UNIX, and is
still very popular. VIM improves on vi by adding new features:
multiple windows, multi-level undo, block highlighting and more.
Update Information:
patchlevel 280 Security fix for CVE-2026-34714, CVE-2026-35177, CVE-2026-34982
* Thu Apr 2 2026 Zdenek Dohnal
[ 1 ] Bug #2453139 - CVE-2026-34714 vim: Vim: Arbitrary code execution via crafted file
https://bugzilla.redhat.com/show_bug.cgi?id=2453139
[ 2 ] Bug #2455400 - CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass
https://bugzilla.redhat.com/show_bug.cgi?id=2455400
[ 3 ] Bug #2455542 - CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass
https://bugzilla.redhat.com/show_bug.cgi?id=2455542
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-251d74645b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.